論文の概要: Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting
- arxiv url: http://arxiv.org/abs/2607.07433v1
- Date: Wed, 08 Jul 2026 14:02:14 GMT
- ステータス: 翻訳完了
- システム内更新日: 2026-07-09 22:50:30.40166
- Title: Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting
- Title(参考訳): エージェントボットネットの注意: ユニバーサルおよびトランスファー可能な敵ハルースクワットによるスケーラブルな未ターゲティング・プロンプトウェア攻撃
- Authors: Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool, Ben Nassi,
- Abstract要約: 資源識別子を幻覚させる LLM の固有の傾向は、未目標のプロンプトウェア攻撃を増幅するために活用できることを示す。
本稿では,攻撃者がトレンドリソースを識別し,敵のプロンプトに登録する手法である,敵の幻覚スクワットについて紹介する。
基礎的なLCMとアプリケーション層間の幻覚の予測可能性と伝達可能性を活用することで、敵は未目標のプロンプトウェアのリーチを著しく増幅することができる。
- 参考スコア(独自算出の注目度): 10.894389368294968
- License: http://creativecommons.org/licenses/by/4.0/
- Abstract: The growing adoption of agentic LLM applications has introduced a new threat previously named as promptware. While prior work has established that adversaries can exploit direct channels to LLM applications to apply promptware under weak threat models, many applications do not provide any direct channels that could be exploited for prompt injection beyond the Internet. This raises a question: can attackers exploit LLM applications at scale without any direct channels in practical threat models? In this work, we show that the inherent tendency of LLMs to hallucinate resource identifiers can be exploited to amplify untargeted promptware attacks that pull adversarial prompts at scale and could be exploited to establish a botnet. We introduce adversarial hallucination squatting, a technique in which attackers identify trending resources (e.g., popular repositories, popular skills, etc.), compute the LLM distribution of hallucinations on the trending resource names, and preemptively register them to host adversarial prompts. By leveraging the predictability and transferability of hallucinations across foundational LLMs and to application layers, adversaries can significantly amplify the reach of untargeted promptware under weak threat models and establish a botnet by exploiting LLM applications to install a bot on the device that pulled the compromised hallucinated resource from the Inter. We empirically demonstrate that hallucinated resource generation occurs at high rates, up to 85% in repository cloning scenarios and up to 100% in skill installation, and that these hallucinations transfer between foundational models and different prompts. We demonstrate the practicality of adversarial hallucination squatting against various production LLM applications with integrated terminals in their set of tools, achieving remote tool execution and remote code execution.
- Abstract(参考訳): エージェントLLMアプリケーションの普及により、以前プロンプトウェアと呼ばれていた新しい脅威がもたらされた。
以前の研究で、敵はLSMアプリケーションへの直接チャネルを利用して、弱い脅威モデルの下でプロンプトウェアを適用できることが証明されているが、多くのアプリケーションはインターネット以外のプロンプトインジェクションに利用できるような直接チャネルを提供していない。
攻撃者は、実用的な脅威モデルで直接チャネルを使わずに、LLMアプリケーションを大規模に利用できますか?
本研究では, LLMが資源識別子を幻覚させる傾向を生かして, 大規模に敵のプロンプトを引っ張り出し, ボットネットの確立に活用できる未目標のプロンプトウェア攻撃を増幅できることを示す。
攻撃者がトレンドリソース(例えば、人気リポジトリ、人気スキルなど)を識別し、トレンドリソース名に基づく幻覚のLLM分布を計算し、事前に敵のプロンプトに登録する手法である逆向き幻覚スクワットを導入する。
基本LPMとアプリケーション層間の幻覚の予測可能性と伝達性を活用することで、敵は弱い脅威モデルの下で未ターゲットのプロンプトウェアのリーチを著しく増幅し、LSMアプリケーションを利用してインターから妥協した幻覚リソースを引き出したデバイスにボットをインストールすることでボットネットを確立することができる。
幻覚発生は,リポジトリのクローニングシナリオで最大85%,スキルインストールで最大100%,そして基礎モデルと異なるプロンプト間での幻覚が伝達されることを実証的に実証した。
ツールセットに端末を組み込んだ多種多様なLLMアプリケーションに対して,遠隔ツールの実行とリモートコード実行を実現するための対向幻覚の実用性を実証する。
関連論文リスト
- Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous [4.172921042226532]
本稿では,エンドユーザーに対するプロンプトウェアリスクを評価するための新しい脅威分析・リスクアセスメントフレームワークを提案する。
5つの脅威クラスにまたがって、ジェミニ駆動のアシスタントに対して14の攻撃シナリオを適用した。
我々のTARAは、分析された脅威の73%がエンドユーザーに高い批判的リスクをもたらすことを明らかにした。
論文 参考訳(メタデータ) (2025-08-16T22:56:51Z) - AgentVigil: Generic Black-Box Red-teaming for Indirect Prompt Injection against LLM Agents [54.29555239363013]
本稿では,間接的なインジェクション脆弱性を自動的に検出し,悪用するための汎用的なブラックボックスファジリングフレームワークであるAgentVigilを提案する。
我々はAgentVigilをAgentDojoとVWA-advの2つの公開ベンチマークで評価し、o3-miniとGPT-4oに基づくエージェントに対して71%と70%の成功率を達成した。
攻撃を現実世界の環境に適用し、悪質なサイトを含む任意のURLに誘導するエージェントをうまく誘導する。
論文 参考訳(メタデータ) (2025-05-09T07:40:17Z) - Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks [88.84977282952602]
最近のMLセキュリティ文献は、整列型大規模言語モデル(LLM)に対する攻撃に焦点を当てている。
本稿では,LLMエージェントに特有のセキュリティとプライバシの脆弱性を分析する。
我々は、人気のあるオープンソースおよび商用エージェントに対する一連の実証的な攻撃を行い、その脆弱性の即時的な影響を実証した。
論文 参考訳(メタデータ) (2025-02-12T17:19:36Z) - Human-Interpretable Adversarial Prompt Attack on Large Language Models with Situational Context [49.13497493053742]
本研究は,無意味な接尾辞攻撃を状況駆動型文脈書き換えによって意味のあるプロンプトに変換することを検討する。
我々は、独立して意味のある敵の挿入と映画から派生した状況を組み合わせて、LLMを騙せるかどうかを確認します。
当社のアプローチでは,オープンソースとプロプライエタリなLLMの両方で,状況駆動型攻撃を成功させることが実証されている。
論文 参考訳(メタデータ) (2024-07-19T19:47:26Z) - Not what you've signed up for: Compromising Real-World LLM-Integrated
Applications with Indirect Prompt Injection [64.67495502772866]
大規模言語モデル(LLM)は、様々なアプリケーションに統合されつつある。
本稿では、プロンプトインジェクション攻撃を用いて、攻撃者が元の命令をオーバーライドし、制御を採用する方法を示す。
我々は、コンピュータセキュリティの観点から、影響や脆弱性を体系的に調査する包括的な分類法を導出する。
論文 参考訳(メタデータ) (2023-02-23T17:14:38Z)
関連論文リストは本サイト内にある論文のタイトル・アブストラクトから自動的に作成しています。
指定された論文の情報です。
本サイトの運営者は本サイト(すべての情報・翻訳含む)の品質を保証せず、本サイト(すべての情報・翻訳含む)を使用して発生したあらゆる結果について一切の責任を負いません。